ืืื ืืขืจ ืคืึทืจืืึทื ืืขื ืืืื
ืืขืจ ืงืืจืก ืืื ื ืืฉื ืืขืงื ืื ืื ืกืืึทืืืจืื ื ืคืื ELK ืกืืึทืง, ืืืืึทื ืขืก ืืขื ืขื ืึท ืจืืืืง ื ืืืขืจ ืคืื ืึทืจืืืงืืขื ืืืืฃ ืืขื ืืขืืข; ืืืจ ืืืขืื ืืึทืืจืึทืืื ืื ืงืึทื ืคืืืืขืจืืืฉืึทื ืงืึธืืคึผืึธื ืขื ื.
ืืึธืืืจ ืืึทืื ืึทื ืึทืงืฆืืข ืคึผืืึทื ืคึฟืึทืจ Logstash ืงืึทื ืคืืืืขืจืืืฉืึทื:
- ืงืึธื ืืจืึธืืืจื ืึทื Elasticsearch ืืืขื ืึธื ื ืขืืขื ืืึธืืก (ืงืึธื ืืจืึธืืืจื ืื ืคืึทื ืืงืฉืึทื ืึทืืืื ืืื ืึธืืคึผืึทื ื ืึทืก ืคืื ืื ืคึผืึธืจื).
- ืืืจ ืืึทืืจืึทืืื ืืื ืืืจ ืงืขื ืขื ืฉืืงื events ืฆื Logstash, ืงืืืึทืื ืึท ืืืคึฟื ืืื ืื ืกืืจืืืขื ื ืขืก.
- ืืืจ ืงืึทื ืคืืืืขืจ ืึทืจืืึทื ืฉืจืืึทื ืืื ืื Logstash ืงืึทื ืคืืืืขืจืืืฉืึทื ืืขืงืข.
- ืืืจ ืงืึทื ืคืืืืขืจ ืจืขืืืืืึทื ืืื ืื Logstash ืงืึทื ืคืืืืขืจืืืฉืึทื ืืขืงืข ืืื ืืืืึทื ืืึธืืข ืฆื ืคึฟืึทืจืฉืืืื ืืื ืื ืงืืึธืฅ ืึธื ืืึธื ืงืืงื ืืื.
- ืืึทืฉืืขืืืงื ืคืืืืขืจ.
- ืืึทืฉืืขืืืงื ืื ืจืืืืืง ืจืขืืืืืึทื ืืื ElasticSearch.
- Logstash ืืึธื ืืฉืื.
- ืงืึธื ืืจืึธืืืจื ืื ืืึธืืก ืืื ืงืืืึทื ืึท.
ืืื ืก ืงืืง ืืื ืืขืืขืจ ืคืื ื ืืื ืืขืจ ืืขืืึทื:
ืงืึธื ืืจืึธืืืจื ืึทื Elasticsearch ืืืขื ืึธื ื ืขืืขื ืืึธืืก
ืฆื ืืึธื ืืึธืก, ืืืจ ืงืขื ืขื ื ืืฆื ืื ืงืขืจื ืืึทืคึฟืขื ืฆื ืงืึธื ืืจืึธืืืจื ืึทืงืกืขืก Elasticsearch ืคึฟืื ืื ืกืืกืืขื ืืืืฃ ืืืึธืก Logstash ืืื ืืืคึผืืืื. ืืืื ืืืจ ืืึธืื ืึธืืขื ืืึทืงืืืฉืึทื ืงืึทื ืคืืืืขืจื, ืืืจ ืืืื ืึทืจืืืขืจืคืืจื ืื ืืึทื ืืฆืขืจ / ืคึผืึทืจืึธื ืืืจื ืงืขืจื, ืกืคึผืขืฆืืคืืฆืืจื ืคึผืึธืจื 9200 ืืืื ืืืจ ืืึธื ื ืืฉื ืืฉืืื ืืืฉื ืขืก. ืืืื ืืืจ ืืึทืงืืืขื ืึทื ืขื ืืคืขืจ ืขื ืืขื ืฆื ืืขืจ ืืื ืื, ืึทืืฅ ืืื ืืื ืกืืจ.
[elastic@elasticsearch ~]$ curl -u <<user_name>> : <<password>> -sS -XGET "<<ip_address_elasticsearch>>:9200"
{
"name" : "elastic-1",
"cluster_name" : "project",
"cluster_uuid" : "sQzjTTuCR8q4ZO6DrEis0A",
"version" : {
"number" : "7.4.1",
"build_flavor" : "default",
"build_type" : "rpm",
"build_hash" : "fc0eeb6e2c25915d63d871d344e3d0b45ea0ea1e",
"build_date" : "2019-10-22T17:16:35.176724Z",
"build_snapshot" : false,
"lucene_version" : "8.2.0",
"minimum_wire_compatibility_version" : "6.8.0",
"minimum_index_compatibility_version" : "6.0.0-beta1"
},
"tagline" : "You Know, for Search"
}
[elastic@elasticsearch ~]$
ืืืื ืืขืจ ืขื ืืคืขืจ ืืื ื ืืฉื ืืืงืืืขื, ืขืก ืงืขื ืืืื ืขืืืขืืข ืืืืคึผืก ืคืื ืขืจืจืึธืจืก: ืื Elasticsearch ืคึผืจืึธืฆืขืก ืืื ื ืืฉื ืคืืืกื ืืืง, ืื ืคืึทืืฉ ืคึผืึธืจื ืืื ืกืคึผืขืกืืคืืขื, ืึธืืขืจ ืื ืคึผืึธืจื ืืื ืืคืืขืฉืืขืื ืืืจื ืึท ืคืืืจืืืึทื ืืืืฃ ืื ืกืขืจืืืขืจ ืืื Elasticsearch ืืื ืืื ืกืืึทืืืจื.
ืืื ืก ืงืืง ืืื ืืืจ ืงืขื ืขื ืฉืืงื ืืึธืืก ืฆื Logstash ืคึฟืื ืึท ืืฉืขืง ืคืื ื ืคืืืจืืืึทื
ืคึฟืื ืืฉืขืง ืคึผืืื ื ืคืึทืจืืืึทืืืื ื ืกืขืจืืืขืจ ืืืจ ืงืขื ืขื ืฉืืงื ืืึธืืก ืฆื Logstash ืืืจื ืกืืกืืึธื ื ืืฆื ืื log_exporter ื ืืฆื, ืืืจ ืงืขื ืขื ืืืืขื ืขื ืืขืจ ืืืขืื ืืื ืืึธ
cp_log_export ืืืืื ื ืึธืืขื ืืฉืขืง_ืคึผืึธืื ื_ืกืืกืืึธื ืฆืื-ืกืขืจืืืขืจ < > ืฆืื-ืคึผืึธืจื 5555 ืคึผืจืึธืืึธืงืึธื ืืงืคึผ ืคึฟืึธืจืืึทื ืืืฉืึทื ืขืจืืง ืืืืขื ืขื-ืืึธืืข ืืึทืื-ืื ืึทืคืืื
< > - ืึทืืจืขืก ืคืื ืื ืกืขืจืืืขืจ ืืืืฃ ืืืึธืก Logstash ืืืืคื, ืฆืื-ืคึผืึธืจื 5555 - ืคึผืึธืจื ืฆื ืืืึธืก ืืืจ ืืืขืื ืฉืืงื ืืึธืืก, ืฉืืงื ืืึธืืก ืืืจื tcp ืงืขื ืขื ืืึธืื ืื ืกืขืจืืืขืจ, ืึทืืื ืืื ืขืืืขืืข ืงืึทืกืขืก ืขืก ืืื ืืขืจ ืจืืืืืง ืฆื ื ืืฆื ืืืคึผ.
ืืึทืฉืืขืืืงื ืื ืคึผืื ืืื ืื Logstash ืงืึทื ืคืืืืขืจืืืฉืึทื ืืขืงืข
ืืืจื ืคืขืืืงืืึทื, ืื ืงืึทื ืคืืืืขืจืืืฉืึทื ืืขืงืข ืืื ืืืื ืืื ืื /etc/logstash/conf.d/ ืืืขืืืืืึทืืขืจ. ืื ืงืึทื ืคืืืืขืจืืืฉืึทื ืืขืงืข ืืืฉืืืื ืคืื 3 ืืื ืื ืืคืึทื ืคึผืึทืจืฅ: ืื ืคึผืื, ืคืืืืขืจ, ืจืขืืืืืึทื. ืืื ืึทืจืืึทื ืฉืจืืึทื ืืืจ ืึธื ืืืืึทืื ืืื ืื ืกืืกืืขื ืืืขื ื ืขืืขื ืืึธืืก ืคืื, ืืื ืคืืืืขืจ ืคึผืึทืจืก ืื ืงืืึธืฅ - ืฉืืขืื ืึทืจืืืฃ ืืื ืฆื ืืืืื ืืขื ืึธื ืืึธื ืืื ืคืขืืืขืจ ืืื ืืืึทืืืขืก, ืืื ืจืขืืืืืึทื ืืืจ ืงืึทื ืคืืืืขืจ ืื ืจืขืืืืืึทื ืืืึทื - ืืื ืื ืคึผืึทืจืกืขื ืืึธืืก ืืืขื ืืืื ืืขืฉืืงื.
ืขืจืฉืืขืจ, ืืึธืื ืืื ืื ืงืึทื ืคืืืืขืจ INPUT, ืืึทืืจืึทืืื ืขืืืขืืข ืืืืคึผืก ืืืึธืก ืงืขื ืขื ืืืื - ืืขืงืข, tcp ืืื exe.
ืืงืคึผ:
input {
tcp {
port => 5555
host => โ10.10.1.205โ
type => "checkpoint"
mode => "server"
}
}
ืืึธืืข => "ืกืขืจืืืืจืขืจ"
ืื ืืืงืืืฅ ืึทื Logstash ืืื ืึทืงืกืขืคึผืืื ื ืงืึทื ืขืงืฉืึทื ื.
ืคึผืึธืจื => 5555
ืืึทืืขืืึธืก => "10.10.1.205"
ืืืจ ืึธื ื ืขืืขื ืงืึทื ืขืงืฉืึทื ื ืืืจื IP ืึทืืจืขืก 10.10.1.205 (ืืึธืืกืืืฉ), ืคึผืึธืจื 5555 - ืื ืคึผืึธืจื ืืืื ืืืื ืขืจืืืืื ืืืจื ืื ืคืืืจืืืึทื ืคึผืึธืืืืืง.
ืืืคึผ => "ืืฉืขืงืคึผืืื ื"
ืืืจ ืฆืืืื ืืขื ืืึธืงืืืขื ื, ืืืืขืจ ืืึทืงืืืขื ืืืื ืืืจ ืืึธืื ืขืืืขืืข ืื ืงืึทืืื ื ืงืึทื ืขืงืฉืึทื ื. ืืขืจื ืึธื, ืคึฟืึทืจ ืืขืืขืจ ืงืฉืจ ืืืจ ืงืขื ืขื ืฉืจืืึทืื ืืืื ืืืืืขื ืข ืคืืืืขืจ ืืื ืื ืืึทืืืฉืืงืึทื ืืืื ืืืืขื.
ืืขืงืข:
input {
file {
path => "/var/log/openvas_report/*"
type => "openvas"
start_position => "beginning"
}
}
ืืึทืฉืจืืึทืืื ื ืคืื ืกืขืืืื ืืก:
ืืจื => "/ืืืึทืจ/ืืึธื/ืึธืคึผืขื ืขืืืึทืก_ืจืขืคึผืึธืจื/*"
ืืืจ ืึธื ืืืืึทืื ืื ืืืขืืืืืึทืืขืจ ืืื ืืืึธืก ืื ืืขืงืขืก ืืึทืจืคึฟื ืฆื ืืืื ืืืืขื ืขื.
ืืืคึผ => "ืึธืคึผืขื ืขืืืึทืก"
ืืขืฉืขืขื ืืฉ ืืืคึผ.
start_position => "ืึธื ืืืื"
ืืืขื ืืฉืึทื ืืื ื ืึท ืืขืงืข, ืขืก ืืืืขื ื ืื ืืื ืฆืข ืืขืงืข; ืืืื ืืืจ ืฉืืขืื "ืกืืฃ", ืื ืกืืกืืขื ืืืืืฅ ืคึฟืึทืจ ื ืืึทืข ืจืขืงืึธืจืืก ืฆื ืืขืจืฉืืึทื ืขื ืืื ืื ืกืืฃ ืคืื ืืขืจ ืืขืงืข.
ืขืงืกืขืง:
input {
exec {
command => "ls -alh"
interval => 30
}
}
ื ืืฆื ืืขื ืึทืจืืึทื ืฉืจืืึทื, ืึท (ืืืืื!) ืฉืึธื ืืึทืคึฟืขื ืืื ืืึธื ืืฉื ืืื ืืืึทื ืจืขืืืืืึทื ืืื ืคืืจืงืขืจื ืืื ืึท ืงืืึธืฅ ืึธื ืืึธื.
ืืึทืคึฟืขื => "ืืก -ืึทืื"
ืืขืจ ืืึทืคึฟืขื ืืืขืืขื ืก ืจืขืืืืืึทื ืืืจ ืืขื ืขื ืืื ืืขืจืขืกืืจื ืืื.
ืืขืืึทืืขื => 30
ืืึทืคึฟืขืื ืื ืืืึธืงืึทืืืึธื ืืขืืึทืืขื ืืื ืกืขืงืื ืืขืก.
ืืื ืกืืจ ืฆื ืืึทืงืืืขื ืืึธืืก ืคืื ืื ืคืืืจืืืึทื, ืืืจ ืจืขืืืกืืจืืจื ืึท ืคืืืืขืจ tcp ืึธืืขืจ ืคึผืื, ืืืคึผืขื ืืื ื ืืืืฃ ืืื ืื ืืึธืืก ืืขื ืขื ืืขืฉืืงื ืฆื Logstash.
ืืืจ ืงืึทื ืคืืืืขืจ ืจืขืืืืืึทื ืืื ืื Logstash ืงืึทื ืคืืืืขืจืืืฉืึทื ืืขืงืข ืืื ืืืืึทื ืืึธืืข ืฆื ืคึฟืึทืจืฉืืืื ืืื ืื ืงืืึธืฅ ืึธื ืืึธื ืงืืงื ืืื
ื ืึธื ืืืจ ืืึธืื ืงืึทื ืคืืืืขืจื INPUT, ืืืจ ืืึทืจืคึฟื ืฆื ืคึฟืึทืจืฉืืืื ืืื ืื ืงืืึธืฅ ืึธื ืืึธื ืืืขื ืงืืงื ืืื ืืื ืืืึธืก ืืขืืืึธืืก ืืึทืจืคึฟื ืฆื ืืืื ืืขืืืืื ื ืฆื ืงืึทื ืคืืืืขืจ ืื ืงืืึธืฅ ืคืืืืขืจ (ืคึผืึทืกืขืจ).
ืฆื ืืึธื ืืึธืก, ืืืจ ืืืขืื ื ืืฆื ืึท ืคืืืืขืจ ืืืึธืก ืึทืืืคึผืืฅ ืื ืจืขืืืืืึทื ืฆื ืกืืืึธืื ืฆื ืืขื ืื ืึธืจืืืื ืขื ืึธื ืืึธื; ืื ืืึทื ืฅ ืงืึทื ืคืืืืขืจืืืฉืึทื ืืขืงืข ืืื ืืขื ืืึธืืขื ื ืืืขื ืงืืงื ืืื ืืึธืก:
input
{
tcp
{
port => 5555
type => "checkpoint"
mode => "server"
host => โ10.10.1.205โ
}
}
output
{
if [type] == "checkpoint"
{
stdout { codec=> json }
}
}
ืืืืคื ืื ืืึทืคึฟืขื ืฆื ืงืึธื ืืจืึธืืืจื:
sudo /usr/share/logstash/bin//logstash -f /etc/logstash/conf.d/checkpoint.conf
ืืืจ ืืขื ืื ืจืขืืืืืึทื, ืื ืืืื ืืื ืงืืืงืงืึทืืืข:
ืืืื ืืืจ ื ืึธืืืึทืื ืขืก, ืขืก ืืืขื ืงืืงื ืืื ืืึธืก:
action="Accept" conn_direction="Internal" contextnum="1" ifdir="outbound" ifname="bond1.101" logid="0" loguid="{0x5dfb8c13,0x5,0xfe0a0a0a,0xc0000000}" origin="10.10.10.254" originsicname="CN=ts-spb-cpgw-01,O=cp-spb-mgmt-01.tssolution.local.kncafb" sequencenum="8" time="1576766483" version="5" context_num="1" dst="10.10.10.10" dst_machine_name="[email protected]" layer_name="TSS-Standard Security" layer_name="TSS-Standard Application" layer_uuid="dae7f01c-4c98-4c3a-a643-bfbb8fcf40f0" layer_uuid="dbee3718-cf2f-4de0-8681-529cb75be9a6" match_id="8" match_id="33554431" parent_rule="0" parent_rule="0" rule_action="Accept" rule_action="Accept" rule_name="Implicit Cleanup" rule_uid="6dc2396f-9644-4546-8f32-95d98a3344e6" product="VPN-1 & FireWall-1" proto="17" s_port="37317" service="53" service_id="domain-udp" src="10.10.1.180" ","type":"qqqqq","host":"10.10.10.250","@version":"1","port":50620}{"@timestamp":"2019-12-19T14:50:12.153Z","message":"time="1576766483" action="Accept" conn_direction="Internal" contextnum="1" ifdir="outbound" ifname="bond1.101" logid="0" loguid="{0x5dfb8c13,
ืงืืงื ืืื ืื ืึทืจืืืงืืขื, ืืืจ ืคึฟืึทืจืฉืืืื ืึทื ืื ืืึธืืก ืงืืงื ืืื: ืคืขืื = ืืืขืจื ืึธืืขืจ ืฉืืืกื = ืืืขืจื, ืืืึธืก ืืืื ืึท ืคืืืืขืจ ืืขืจืืคื kv ืืื ืคึผืึทืกืืง. ืืื ืกืืจ ืฆื ืงืืืึทืื ืื ืจืขืื ืคืืืืขืจ ืคึฟืึทืจ ืืขืืขืจ ืกืคึผืขืฆืืคืืฉ ืคืึทื, ืขืก ืืืึธืื ืืืื ืึท ืืืืข ืืขืืึทื ืง ืฆื ืืืื ืืึทืงืึทื ื ืืื ืืื ืืื ืื ืืขืื ืืฉ ืืึทืงืืืืขื ืืืืฉืึทื, ืึธืืขืจ ืคืจืขืื ืึท ืคืจืืึทื ื.
ืืึทืฉืืขืืืงื ืคืืืืขืจ
ืืื ืื ืืขืฆืืข ืืื ืข ืืืจ ืืืืกืืขืงืืืื ืงืื, ืื ืงืึทื ืคืืืืขืจืืืฉืึทื ืคืื ืืขื ืคืืืืขืจ ืืื ืืขืจืืื ืื ืืื ืื:
filter {
if [type] == "checkpoint"{
kv {
value_split => "="
allow_duplicate_values => false
}
}
}
ืืืจ ืกืขืืขืงืืืจื ืืขื ืกืืืืึธื ืืื ืืืึธืก ืืืจ ืืืืื ืื ืคืขืื ืืื ืืืขืจื - "=". ืืืื ืืืจ ืืึธืื ืืืืขื ืืงืึทื ืืืื ืกื ืืื ืื ืงืืึธืฅ, ืืืจ ืจืึทืืขืืืขื ืืืืื ืืืื ืืืึทืฉืคึผืื ืืื ืื ืืึทืืึทืืืืก, ืึทื ืืขืจืฉ ืืืจ ืืืขื ืกืืฃ ืึทืจืืืฃ ืืื ืึท ืืขื ืืข ืคืื โโืืืืขื ืืงืึทื ืืืึทืืืขืก, ืืึธืก ืืื, ืืืื ืืืจ ืืึธืื ืื ืึธื ืืึธื "foo = some foo = some" ืืืจ ืฉืจืืึทืื ืืืืื foo. = ืขืืืขืืข.
ืืึทืฉืืขืืืงื ืื ืจืืืืืง ืจืขืืืืืึทื ืืื ElasticSearch
ืึทืืึธื ืคืืืืขืจ ืืื ืงืึทื ืคืืืืขืจื, ืืืจ ืงืขื ืขื ืืคึผืืึธืึทื ืืึธืืก ืฆื ืื ืืึทืืึทืืืืก ืืืืข ืืืื:
output
{
if [type] == "checkpoint"
{
elasticsearch
{
hosts => ["10.10.1.200:9200"]
index => "checkpoint-%{+YYYY.MM.dd}"
user => "tssolution"
password => "cool"
}
}
}
ืืืื ืืขืจ ืืึธืงืืืขื ื ืืื ืืขืืชืืขื ืืื ืื ืืฉืขืงืคึผืืื ื ืืืคึผ, ืืืจ ืจืึทืืขืืืขื ืื ืืขืฉืขืขื ืืฉ ืืื ืื Elasticsearch ืืึทืืึทืืืืก, ืืืึธืก ืึทืงืกืขืคึผืฅ ืงืึทื ืขืงืฉืึทื ื ืืืืฃ 10.10.1.200 ืืืืฃ ืคึผืึธืจื 9200 ืืืจื ืคืขืืืงืืึทื. ืืขืืขืจ ืืึธืงืืืขื ื ืืื ืืขืจืืืขืืืขื ืฆื ืึท ืกืคึผืขืฆืืคืืฉ ืืื ืืขืงืก, ืืื ืืขื ืคืึทื ืืืจ ืจืึทืืขืืืขื ืฆื ืื ืืื ืืขืงืก "ืืฉืขืงืคึผืืื ื-" + ืงืจืึทื ื ืฆืืื ืืึธื. ืืขืืขืจ ืืื ืืขืงืก ืงืขื ืขื ืืึธืื ืึท ืกืคึผืขืฆืืคืืฉ ืืึทื ื ืคืื ืคืขืืืขืจ, ืึธืืขืจ ืืื ืืืฉืืคื ืืืืืึธืืึทืืืฉ ืืืขื ืึท ื ืืึทืข ืคืขืื ืืื ืืจืืืก ืืื ืึท ืึธื ืืึธื; ืคืขืื ืกืขืืืื ืืก ืืื ืืืืขืจ ืืืคึผ ืงืขื ืขื ืืืื ืืืืื ืืื ืืึทืคึผืื ืื.
ืืืื ืืืจ ืืึธืื ืึธืืขื ืืึทืงืืืฉืึทื ืงืึทื ืคืืืืขืจื (ืืืจ ืืืขืื ืืขื ืขืก ืฉืคึผืขืืขืจ), ืื ืงืจืึทืืขื ืืฉืึทืื ืคึฟืึทืจ ืฉืจืืืื ืฆื ืึท ืกืคึผืขืฆืืคืืฉ ืืื ืืขืงืก ืืืื ืืืื ืกืคึผืขืกืืคืืขื, ืืื ืืขื ืืืึทืฉืคึผืื ืขืก ืืื "ืฆืกืึทืืืฉืึทื" ืืื ืื ืคึผืึทืจืึธื "ืงืื". ืืืจ ืงืขื ืขื ืืืคืขืจืขื ืฉืืืื ืืึทื ืืฆืขืจ ืจืขืื ืฆื ืฉืจืืึทืื ืืึธืืก ืืืืื ืฆื ืึท ืกืคึผืขืฆืืคืืฉ ืืื ืืขืงืก ืืื ื ืื ืืขืจ.
ืงืึทืืขืจ Logstash.
Logstash ืงืึทื ืคืืืืขืจืืืฉืึทื ืืขืงืข:
input
{
tcp
{
port => 5555
type => "checkpoint"
mode => "server"
host => โ10.10.1.205โ
}
}
filter {
if [type] == "checkpoint"{
kv {
value_split => "="
allow_duplicate_values => false
}
}
}
output
{
if [type] == "checkpoint"
{
elasticsearch
{
hosts => ["10.10.1.200:9200"]
index => "checkpoint-%{+YYYY.MM.dd}"
user => "tssolution"
password => "cool"
}
}
}
ืืืจ ืงืึธื ืืจืึธืืืจื ืื ืงืึทื ืคืืืืขืจืืืฉืึทื ืืขืงืข ืคึฟืึทืจ ืจืืืืืง:
/usr/share/logstash/bin//logstash -f checkpoint.conf
ืึธื ืืืื ืืขื Logstash ืคึผืจืึธืฆืขืก:
ืกืืืึธ ืกืืกืืขืืงืื ืึธื ืืืื ืืึธืืกืืึทืฉ
ืืืจ ืงืึธื ืืจืึธืืืจื ืึทื ืืขืจ ืคึผืจืึธืฆืขืก ืืื ืกืืึทืจืืขื:
sudo systemctl ืกืืึทืืืก ืืึธืืกืืึทืฉ
ืืื ืก ืืฉืขืง ืืืื ืื ืืึธืืขื ืืื ืึทืจืืืฃ:
netstat -nat |grep 5555
ืงืึธื ืืจืึธืืืจื ืื ืืึธืืก ืืื ืงืืืึทื ืึท.
ื ืึธื ืึทืืฅ ืืื ืคืืืกื ืืืง, ืืืื ืฆื Kibana - ืึทื ืืืขืงื, ืืึทืื ืืืืขืจ ืึทื ืึทืืฅ ืืื ืงืึทื ืคืืืืขืจื ืจืืืืืง, ืื ืืืื ืืื ืงืืืงืงืึทืืืข!
ืึทืืข ืืึธืืก ืืขื ืขื ืืื ืคึผืืึทืฅ ืืื ืืืจ ืงืขื ืขื ืืขื ืึทืืข ืื ืคืขืืืขืจ ืืื ืืืืขืจ ืืืึทืืืขืก!
ืกืึธืฃ
ืืืจ ืืขืงืืงื ืืืืฃ ืืื ืฆื ืฉืจืืึทืื ืึท Logstash ืงืึทื ืคืืืืขืจืืืฉืึทื ืืขืงืข, ืืื ืืื ืึท ืจืขืืืืืึทื ืืืจ ืืึทืงืืืขื ืึท ืคึผืึทืจืกืขืจ ืคืื ืึทืืข ืคืขืืืขืจ ืืื ืืืึทืืืขืก. ืืืฆื ืืืจ ืงืขื ืขื ืึทืจืืขืื ืืื ืืืื ืืื ืคึผืืึทืืื ื ืคึฟืึทืจ ืกืคึผืขืฆืืคืืฉ ืคืขืืืขืจ. ืืืืึทืืขืจ ืืื ืืขื ืงืืจืก ืืืจ ืืืขืื ืงืืงื ืืื ืืืืืฉืืืึทืืึทืืืืฉืึทื ืืื ืงืืืึทื ืึท ืืื ืืึทืื ืึท ืคึผืฉืื ืืึทืฉืืึธืจื. ืขืก ืืื ืืืื ืฆื ืืขืจืืึธื ืขื ืึทื ืื Logstash ืงืึทื ืคืืืืขืจืืืฉืึทื ืืขืงืข ืืึทืจืฃ ืงืขืกืืืืขืจ ืืขืจืืืึทื ืืืงื ืืื ืืืืขืจ ืกืืืืึทืืืึธื ืก, ืืืฉื, ืืืขื ืืืจ ืืืืื ืฆื ืคืึทืจืืืึทืื ืื ืืืขืจื ืคืื ืึท ืคืขืื ืคืื ืึท ื ืืืขืจ ืฆื ืึท ืืืึธืจื. ืืื ืกืึทืืกืึทืงืืืึทื ื ืึทืจืืืงืืขื ืืืจ ืืืขืื ืืึธื ืืึธืก ืงืขืกืืืืขืจ.
ืึทืืื ืืืืืื ืืื ื (
ืืงืืจ: www.habr.com